Sponsors
Partners
ArgusLeaf runs on volunteer infrastructure. Hosting companies that operate on networks where phishing is an active problem can partner with us: they provide server resources, and in return they get direct visibility into phishing activity on their own ASN — domains their resolvers are serving, threats their customers are hitting.
This isn't a commercial relationship. There are no SLAs, no paid tiers, no priority queue. It's an exchange between people who take phishing seriously.
What you get
Partnership is defined by what we can actually deliver as a volunteer-run project. We set clear boundaries up front so nobody's expectations are misaligned.
| What we offer | What we can't promise |
|---|---|
| ✓ "Infrastructure partner" credit on this page | ✗ SLA or uptime guarantees |
| ✓ API access to phishing threats on your ASN / CIDR ranges | ✗ Real-time alerting (API is pull-based) |
| ✓ RPZ (DNS blocklist) feed for your resolvers | ✗ False-positive rate guarantees |
| ✓ DNS telemetry ingestion — your resolvers feed us, we score the domains | ✗ Dedicated support channel or response time |
| ✓ Equal standing — no tiered hierarchy between partners | ✗ Cash payments or revenue share |
DNS telemetry
Partner companies can run our open-source agent on their resolver nodes. The agent reads unbound, BIND9, or Windows DNS query logs, batches domains every five minutes, and sends them to ArgusLeaf's pipeline. We score them — the result goes back through the partner's threat API and RPZ feed.
No raw logs leave your network. The agent sends only resolved domain names (no client IPs, no query metadata). You control the deployment and can stop it at any time.
The agent is a single static Go binary — no runtime dependencies, no telemetry of its own.
View agent sourceBecome a partner
Write to [email protected] with your company name, ASN, and a brief note on what you'd like to contribute (server, CIDR visibility, both).
We discuss your network footprint, what data the API would return, and how the DNS agent fits your resolver stack. No sales, no deck — just a technical conversation.
If you're contributing a server: we deploy an ArgusLeaf worker via Docker. If you're contributing DNS telemetry: we install the agent and walk through the log path together.
We generate a Bearer key scoped to your ASN and CIDR ranges. The key unlocks GET /api/v1/partner/threats and GET /api/v1/partner/rpz-feed.
Your company appears on this page. The relationship continues as long as both sides find it useful — no contract, no lock-in.
Ready to start a conversation? Send a short note to [email protected] — we'll get back within a few days.